[Tickets #14926] Re: Horde Webmail - XSS + CSRF to SQLi, RCE, Stealing Emails <= v5.2.22
[email protected] Wed, 04 Dec 2019 00:44:21 +0000
| Newsgroups | gmane.comp.horde.bugs |
|---|---|
| Message-ID | <[email protected]> |
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED. Ticket URL: https://bugs.horde.org/ticket/14926 ------------------------------------------------------------------------------ Ticket | 14926 Updated By | Michael Rubinsky <[email protected]> Summary | Horde Webmail - XSS + CSRF to SQLi, RCE, Stealing | Emails <= v5.2.22 Queue | Horde Groupware Version | 5.2.22 Type | Bug State | Resolved Priority | 3. High Milestone | Patch | Owners | ------------------------------------------------------------------------------ Michael Rubinsky <[email protected]> (2019-12-04 00:44) wrote: As far as I know those are the only two issues applicable to this ticket. I think the third was the "exploit" of being able to obtain IMAP messages via GET requests, from a webmail application... -- bugs mailing list Frequently Asked Questions: http://wiki.horde.org/FAQ To unsubscribe, mail: [email protected]